SA-CONTRIB-2026-214: Critical severity drupal/permissions_by_term vulnerability
This module enables you to restrict view access to single nodes via taxonomy terms. The module doesn't sufficiently check access rights when in "Permission mode" and a node referencing a deleted taxonomy term is accessed via JSON:API. This vulnerability is mitigated by the fact that it requires a specific module configuration, references to a deleted term, and access via JSON:API to be present.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/permissions_by_termto a version that resolves this vulnerability.Fixed in 3.1.41
Event History
Frequently Asked Questions
Which deployments are exposed?
Exposure requires the module to be configured in Permission mode, nodes that still reference deleted taxonomy terms, and JSON:API access. Deployments missing any of these conditions are mitigated according to the advisory.
What does an attacker need to exploit this issue?
An attacker must access an affected node through JSON:API. The affected node must reference a deleted taxonomy term while the module is operating in Permission mode.
How can I assess whether my site may be affected?
Review the module configuration to determine whether Permission mode is enabled. Then identify nodes with references to deleted taxonomy terms and confirm whether those nodes are accessible through JSON:API.
What can be done if patching is not immediately possible?
Reduce exposure by avoiding Permission mode, remediating node references to deleted taxonomy terms, or restricting JSON:API access. These steps address the conditions identified as necessary for exploitation.